ciso.diy
Both Sides of the MSP preview
Bundles MSP securityMSSPUK Cyber Security and Resilience ActCAF v4.0

Both Sides of the MSP

The duties a UK managed service provider owes, and the assessment its customers are about to run on it. Read your own regime and your customers’ checklist in one purchase. 14% off buying separately.

What this actually gives you

  • Your regulator tells you what you must do; your customers tell you what you must show. Those are different lists, and only one arrives with a deadline attached.
  • Reading the customer checklist before a customer sends it is the cheapest preparation there is — and the assessment is explicit that refusal to evidence a control is itself the finding.
  • It works the other way too: a buyer assessing a UK provider gets the regime that provider is actually subject to, which makes the questions land better than a generic questionnaire.

The fastest way for a managed service provider to pass an assessment is to have already read it.

UK Cyber Security & Resilience Act Kit — the provider-side duties: the scope test that tells you whether you are a relevant MSP, the CAF v4.0 crosswalk across all 39 contributing outcomes, the 24/72-hour notification runbook, the customer-notice duty most MSPs discover mid-incident, designated-supplier readiness, and the map to NIS2 and DORA.

MSP & MSSP Assessment Kit — the buyer's side: what a customer will ask you to evidence about your holdings, every access path into their estate, 40 controls you will be asked to prove, 20 contract clauses measured against UK, DFS, HIPAA, DORA and NIS2 expectations, and a scenario that tests what happens to them the night you are breached.

Why an MSP should own both. Your regulator tells you what you must do. Your customers tell you what you must show — and they are increasingly told to ask by their own regulators, from the DFS third-party service provider letter to HIPAA's annual business-associate verification. Those are different lists, and only one of them arrives with a deadline attached. Reading the customer checklist before a customer sends it is the cheapest form of preparation there is, and the kit is explicit that refusal to evidence a control is itself the finding.

It works the other way too. A buyer running the assessment on a UK provider gets the regime that provider is actually subject to, which makes the questions land better than a generic questionnaire ever does.

Two tiers, because the UK kit is sold as an organisation or an MSSP licence rather than a practitioner one.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-08